Vulnerabilities in Qualcomm, Inc.

2,934 results
Vexday analysis

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2017-18283Possible memory corruption when Read Val Blob Req is received with invalid parameters in Snapdragon Mobile in version QCA9379, SD 210/SD 212EPSS 0.5%CVE-2015-9005In TrustZone in all Android releases from CAF using the Linux kernel, an Integer Overflow to Buffer Overflow vulnerability could potentiallyEPSS 0.5%CVE-2014-9944In the Secure File System in all Android releases from CAF using the Linux kernel, an Integer Overflow to Buffer Overflow vulnerability coulEPSS 0.5%CVE-2023-28588HIGHInteger Overflow or Wraparound in Bluetooth HostEPSS 0.5%CVE-2017-14869In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while performing update of FEPSS 0.5%CVE-2015-0575In all Qualcomm products with Android releases from CAF using the Linux kernel, insecure ciphersuites were included in the default configuraEPSS 0.5%CVE-2021-1906MEDIUMImproper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon ComputEPSS 0.5%KEVCVE-2017-9679In all Qualcomm products with Android releases from CAF using the Linux kernel, if a userspace string is not NULL-terminated, kernel memory EPSS 0.5%CVE-2017-9680In all Qualcomm products with Android releases from CAF using the Linux kernel, if a pointer argument coming from userspace is invalid, a drEPSS 0.5%CVE-2017-18171Improper input validation for GATT data packet received in Bluetooth Controller function can lead to possible memory corruption in SnapdragoEPSS 0.5%CVE-2019-14040Using memory after being freed in qsee due to wrong implementation can lead to unexpected behavior such as execution of unknown code in SnapEPSS 0.5%CVE-2023-33043HIGHReachable Assertion in ModemEPSS 0.5%CVE-2023-33044HIGHReachable Assertion in Data ModemEPSS 0.5%CVE-2018-11279Lack of check of input size can make device memory get corrupted because of buffer overflow in snapdragon automobile, snapdragon mobile and EPSS 0.5%CVE-2017-6421In the touch controller function in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a variable may be controEPSS 0.5%CVE-2020-11155u'Buffer overflow while processing PDU packet in bluetooth due to lack of check of buffer length before copying into it.' in Snapdragon AutoEPSS 0.5%CVE-2020-11154u'Buffer overflow while processing a crafted PDU data packet in bluetooth due to lack of check of buffer size before copying' in Snapdragon EPSS 0.5%CVE-2019-10622Out of bound memory access can happen while parsing ADSP message due to lack of check of size of payload received from userspace in SnapdragEPSS 0.5%CVE-2022-22088CRITICALInteger Overflow to Buffer Overflow in Bluetooth HOSTEPSS 0.5%CVE-2015-9001In TrustZone an information exposure vulnerability can potentially occur in all Android releases from CAF using the Linux kernel.EPSS 0.5%